Splunk
  • Pricing
  • Training
  • Support
    • Support Portal
    • Support Programs
    • Contact Support
    • Splunk Answers
    • Documentation
    • Product Security Updates
    • Getting Started with Splunk Software
    • Community Support
    • Splunk Services
    • Deutsch
    • Español
    • Français
    • Italiano
    • 日本語
    • 한국어
    • Português
    • Pусский
    • 简体中文
    • 繁體中文
    • Login
    • Sign Up
Splunk
  • IT
  • SECURITY
  • IoT
  • BUSINESS ANALYTICS
  • WHY SPLUNK?
  • EXPLORE
    Products | Overview
    CORE
    • Splunk Cloud
    • Splunk Enterprise
    IT OPERATIONS
    • Splunk IT Service Intelligence
    • Splunk Insights for AWS Cloud Monitoring
    • Splunk App for Infrastructure
    • VictorOps
    SECURITY
    • Splunk Enterprise Security
    • Splunk Phantom
    • Splunk User Behavior Analytics
    IoT
    • Splunk for Industrial IoT
    BUSINESS ANALYTICS
    • Splunk Business Flow
    Industries
    • Communications
    • Financial Services
    • Healthcare
    • Public Sector
    • All Industries
    Company
    • About Splunk
    • Customers
    • Partners
    • Splunk Next
    • Trek-Segafredo Partnership
    • Pricing
    • Value Calculator
    • Blogs
    • Free Trials and Downloads
    • Resources
  • Free Splunk
Splunk Free Splunk
Login | Sign Up
IT
SECURITY
IoT
BUSINESS ANALYTICS
WHY SPLUNK?
Products
Overview
  • CORE
  • Splunk Cloud
  • Splunk Enterprise
  • IT OPERATIONS
  • Splunk IT Service Intelligence
  • Splunk Insights for AWS Cloud Monitoring
  • Splunk App for Infrastructure
  • VictorOps
  • SECURITY
  • Splunk Enterprise Security
  • Splunk Phantom
  • Splunk User Behavior Analytics
  • IoT
  • Splunk for Industrial IoT
  • BUSINESS ANALYTICS
  • Splunk Business Flow
Industries
  • Communications
  • Financial Services
  • Healthcare
  • Public Sector
  • All Industries
Company
  • About Splunk
  • Customers
  • Partners
  • Splunk Next
  • Trek-Segafredo Partnership
Pricing
Value Calculator
Blogs
Free Trials and Downloads
Resources
Pricing
Training
Support
  • Support Portal
  • Support Programs
  • Contact Support
  • Splunk Answers
  • Documentation
  • Product Security Updates
  • Getting Started with Splunk Software
  • Community Support
  • Splunk Services
Languages
  • Deutsch
  • Español
  • Français
  • Italiano
  • 日本語
  • 한국어
  • Português
  • Pусский
  • 简体中文
  • 繁體中文
Case Study

Surescripts Protects Doctors and Patients With Improved Fraud Detection and Security

Industry
Healthcare
resource-icon
Download PDF
Splunk at Surescripts

Executive Summary

Founded in 2001, Surescripts operates the largest health information network in the United States, designed to connect a diverse and expansive community of care partners including pharmacies, providers, benefit managers and health information exchanges. With vast amounts of data flowing across its technology-neutral platform, Surescripts needed to maintain a close watch over fraudulent activity and wanted real-time visibility into its entire security posture for faster reporting and incident response. Since deploying Splunk Enterprise, Surescripts has seen benefits including: 

  • Improved fraud detection accuracy
  • Immediate insights into security events
  • Reduced incident response times
SPLUNK PRODUCTS
Splunk Enterprise
Splunk DB Connect
Splunk for Palo Alto Networks
Splunk on Splunk (S.o.S)
Splunk Enterprise Security (planned)
SPLUNK SOLUTION AREAS
Security
Business Analytics
Challenges
    • Safeguarding huge volume of sensitive information
    • Time-consuming manual process for identifying and analyzing fraudulent transactions
    • 24-hour latencies on existing SIEM solution
    • Lack of real-time visibility into processes
Business Impact
    • Increased automation of daily fraud checks on billions of transactions
    • Faster and improved fraud detection accuracy
    • More in-depth real-time and historical data fraud analysis
    • Immediate insights into security events
    • Significantly reduced incident response times
    • Ability to create customized, in-depth, intricate reports
Data Sources
    • 3,000 data sources
    • VPN, firewall and server logs
    • Malware IDs
    • Failed password attempts

Why Splunk

Surescripts processes more than six billion transactions each year, including more than 700 million medication histories, one billion e-prescriptions and nearly ten million clinical messages. Prior to Splunk, identifying and analyzing fraudulent transactions was a tedious, time-consuming process for Surescripts’ Information Security and Risk Management team. The team would receive unique alerts from each disparate platform, decipher each alert individually and then export the associated raw log data into Excel for analysis. Additionally, Surescripts was experiencing 24-hour latencies on investigations with its existing security information and event management (SIEM) system, which was too long of a delay.

Surescripts deployed Splunk Enterprise across its complicated infrastructure—consisting of multiple datacenters and extensive virtual and in-house hardware—for enterprise security and fraud management. “We realized our investment the minute we deployed the Splunk solution. Splunk software has empowered Surescripts to determine what is important—to take full control of all our data,” says Paul Calatayud, Surescripts’ chief information security officer (CISO).

“Healthcare fraud costs medical providers, pharmaceutical companies, pharmacies and patients billions of dollars per year. Surescripts uses Splunk software to pinpoint and help put a stop to those trying to take advantage of our customers,” said Paul Calatayud, chief information security officer, Surescripts.



Read the Press Release

Automating and improving real-time fraud detection

Since deploying Splunk Enterprise, Surescripts has streamlined processes and automated the analysis of fraudulent activity. All raw log event data now comes through the Splunk interface, significantly reducing the time needed to detect, analyze and mitigate fraud.  

With Splunk software, Surescripts now sees patterns within the data that identify physicians who may be self-prescribing medications.  Similarly, Surescripts can recognize legitimate doctors on the network writing valid prescriptions—and protect them from identity theft. More complex fraud queries in Splunk Enterprise have enabled Surescripts to introduce and monitor multiple “risk” variables, such as data about doctors prescribing restricted and commonly abused medications over a set time period in a particular location. Splunk provides historical trending for these variables so that Surescripts can identify pattern anomalies and determine whether a doctor’s credentials have been compromised.

“We realized our investment the minute we deployed the Splunk solution. Splunk software has empowered Surescripts to determine what is important—to take full control of all our data. We’ve been able to expand our scope of fraud detection and improve alerting across our entire platform, enabling faster response to incidents.”



Paul Calatayud, CISO, Surescripts

Replacing a legacy SIEM solution to gain instant answers

After replacing its legacy SIEM solution with Splunk software, Surescripts gained immediate insights from its unstructured data. Calatayud explains, “Splunk allows you to look beyond your data into security areas, so you’re getting an all-encompassing view. Our team’s expertise becomes a key variable in the analysis of what is meaningful. That just can’t be done with your typical SIEM.”

“Not only are we achieving better response times, we’re able to pivot and dig deeper whenever we find something of interest,” says Steve Olson, manager of security services for Surescripts. “We’re able to build velocities around patterns using Splunk’s reporting engine to create intricately customized and in-depth reports. It is much easier to do that with Splunk software than the old SIEM. Moreover, reports that previously took 15 minutes to generate for each state are now generated automatically and instantaneously.”

In addition, Splunk DB Connect gives Surescripts access to data stored in relational databases. Previously, the team logged remotely into the production environment and the needed data wasn’t always available due to dependency on upstream processes. “With DB Connect, as the data shows up, it’s immediately imported. It makes our lives much easier,” Olson explains.

Increased interoperability across entire infrastructure

The Surescripts network integrates with a variety of clinical, electronic prescribing and pharmacy management software systems. Interoperability is critical to these systems, especially in view of increasingly stringent federal regulations for the healthcare industry. Thanks to Splunk software, Surescripts now exchanges and interprets shared data across these internal platforms. This ensures that the electronic exchange of prescription information is carried out smoothly across Surescripts’ entire infrastructure—while safeguarding patient privacy.

Currently, more than 200 individuals across Surescripts use the Splunk reporting interface, including IT, server, network, database and development staff. There are plans for the quality, products and formal business intelligence teams to use the Splunk solution as well. Calatayud concludes, “We’re going to start to see Splunk software move from internal utilization to supporting all our products indirectly.”

PRODUCTS
  • Splunk Cloud
  • Splunk Enterprise
  • Splunk IT Service Intelligence
  • Splunk Insights for AWS Cloud Monitoring
  • Splunk App for Infrastructure
  • VictorOps
  • Splunk Enterprise Security
  • Splunk Phantom
  • Splunk User Behavior Analytics
  • Splunk for Industrial IoT
  • Splunk Business Flow
FREE TRIALS AND DOWNLOADS
PRICING
CALCULATORS
  • Splunk Value Calculator
  • Critical IT Incident Calculator
SOLUTIONS
  • IT
  • Security
  • IoT
  • Business Analytics
INDUSTRIES
  • Aerospace and Defense
  • Communications
  • Energy and Utilities
  • Financial Services
  • Healthcare
  • Higher Education
  • Manufacturing
  • Nonprofits
  • Online Services
  • Public Sector
  • Retail
CUSTOMERS
RESOURCES
  • E-books
  • Recorded Webinars
  • Videos
  • White Papers
  • More...
STRATEGY AND BUSINESS INSIGHTS
  • AI Ops
  • Machine Learning
  • Data Insider
  • Data-to-Everything
  • More...
PARTNERS
  • Become a Partner
  • Partner Login
  • More...
SUPPORT
  • Support Portal
  • Contact Support
  • Splunk Services
  • Support Programs
TRAINING
ABOUT SPLUNK
  • Careers
  • Events
  • Investor Relations
  • Leadership Team
  • Locations
  • Newsroom
  • Splunk for Good
  • Splunk Protects
  • Splunk Ventures
  • More...
CONNECT WITH SPLUNK
  • Support
  • Partners
  • Sales
SPLUNK SITES
  • Splunk Answers
  • Blogs
  • Community
  • .conf
  • Developers
  • Documentation
  • Splunkbase
  • SplunkLive!
  • T-shirt Store
  • User Groups
Splunk
Sitemap | Contact | Careers | Privacy | Terms of Use | Export Control | Modern Slavery Statement
© 2005-2019 Splunk Inc. All rights reserved.
Splunk, Splunk> and Turn Data Into Doing are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.